Skip to main content
Back to the guide
Networking13 min read

Planning a UniFi network: gateways, VLANs and Wi-Fi for SMEs

A sound UniFi network does not start with whichever gateway happens to be popular. It starts with floor plans, applications, endpoints, outage impact and a reliable inventory. This guide explains how SMEs can plan the gateway, switching, PoE, VLANs and Wi-Fi as one coherent system. As of 8 August 2026.

Published on August 8, 2026 · Daniel Gläser

Planning a UniFi network: gateways, VLANs and Wi-Fi for SMEs

1. Site assessment: understand first, select later

The site is assessed before any product is selected. This covers more than network outlets and the rack: internet handoff, floors, cable routes, wall and ceiling construction, existing fibre, power circuits, UPS capacity, third-party systems and possible expansion areas all matter. At the same time, build an endpoint inventory covering workstations, phones, printers, servers, NAS systems, tills, machinery, cameras, access readers, displays and mobile devices.

  • Physical layer: quantity, category and test status of data cabling, patch panels, pathways, rack depth, cooling and power.
  • Logical layer: existing subnets, DHCP and DNS services, static IP addresses, port forwards, VPNs, directory services and exceptional rules.
  • Usage: concurrent users, peak periods, large data flows, real-time applications and devices limited to older Wi-Fi standards.
  • Risk: which interruptions are tolerable, and which systems must continue through an internet, switch or power outage?
  • Growth: additional staff, new rooms, more cameras, VoIP, a second internet circuit or another site.

The assessment deliverable

The result is not a shopping basket. It is a planning sheet covering ports, PoE consumers, bandwidth, networks, protection needs, radio areas, headroom and acceptance criteria. Only then can the appropriate hardware class be derived.

2. Translate requirements into measurable quantities

Words such as fast, secure or resilient are too vague for a design. Every requirement needs a testable measure and a business context. A gigabit internet service, for example, says nothing about whether the firewall can sustain that rate with the intended security features enabled, or whether a narrow link between two switches will become the real bottleneck.

From business request to technical planning quantity
Business requestQuestions to answerTechnical impact
Fast cloud and file accessInternet profile, local flows, concurrent usersWAN capacity, firewall throughput, uplink and client port speed
Stable calls and video meetingsConcurrent calls, mobile use, latency sensitivityWi-Fi capacity, roaming, QoS validation, WAN headroom
Separate guest and device networksWho may reach what, and which services must remain accessible?VLANs, SSIDs, port profiles, firewall and access rules
Cameras and door accessQuantity, recording target, bit rates, power and protection needsPoE budget, switching, storage, dedicated segment, UPS runtime
Continuity during failuresMaximum tolerable interruption for each serviceSpares, redundant paths, second WAN, UPS or high availability
Planning status: 8 August 2026. Sizing depends on the site and applications; exact device limits are checked against current data sheets afterwards.

3. Size the gateway and firewall for the real workload

The gateway connects the internet, internal networks, VPNs and potentially multiple sites. Selecting it by nominal WAN speed alone is therefore insufficient. The decisive case is the most demanding planned workload with every feature that will actually be enabled. That includes firewalling, IDS/IPS, VPN encryption, inter-VLAN traffic, content filtering, multiple WAN links and concurrent connection counts.

  • WAN now and later: contract, physical handoff, possible second provider and likely upgrade during the service life.
  • Security profile: assess throughput with the intended inspection and filtering functions, not only under ideal conditions.
  • VPN: record concurrent remote users and site tunnels, protocol choice and required data rate.
  • Internal routes: traffic between VLANs can load the gateway unless it is handled by suitable Layer 3 components.
  • Hosting model: UniFi Network commonly runs on a Cloud Gateway, but suitable architectures can host it separately.

Describe the cost model accurately

Core UniFi Network management has no mandatory controller license. Optional services such as vendor hosting, enhanced security services or support offerings may carry a charge. This matters to operating cost, but it does not replace technical sizing.

4. Switching and PoE: port count is only one budget

Four budgets are planned in parallel for every switch: port count, port speed, uplink capacity and PoE power. A switch can have enough empty sockets and still be unsuitable because individual ports lack the required PoE class, the total power budget is too small, or several busy access points and servers share a constrained uplink.

Checklist for every planned switch
BudgetPlanning questionCommon mistake
PortsHow many active connections plus defined headroom are required per site and floor?Counting only current endpoints and forgetting uplinks, APs and expansion
SpeedWhich clients and APs need 1, 2.5, 5 or 10 gigabit, and which uplinks need fibre?Fast APs on slow ports or several switches behind one constrained uplink
PoE per portWhich IEEE PoE mode does each endpoint require?The total wattage fits, but an individual port cannot supply the required class
Total PoEWhat is the sum of the maximum power draw of all powered devices?Adding only typical consumption and ignoring future devices
Failure domainWhich services fail if this exact switch or uplink fails?Every critical device depends on one unit with no recovery path
Ubiquiti defines PoE Availability as the total power a switch can distribute to connected devices. It must exceed the sum of their power requirements; current data sheets for the exact models remain authoritative.

Document PoE port by port. For every access point, phone, camera and door controller, record the standard, maximum draw and intended switch port. Allow headroom for startup conditions, model changes and future expansion. Do not confuse passive PoE injectors with negotiated IEEE PoE, and use them only where device compatibility is unambiguous.

5. VLANs: design zones around function and risk

VLANs divide shared infrastructure into virtual networks, but their value comes from a clear rule matrix. A VLAN name does not provide protection on its own. The design must state which traffic between zones is allowed, logged or blocked. UniFi can map Wi-Fi networks and switch ports to fixed VLANs, with dynamic assignment available for more complex environments.

A pragmatic segmentation model for an SME
ZoneTypical participantsDefault principle
ManagementGateways, switches, access points, controllerReachable only from defined administration devices and services
EmployeesManaged PCs and laptopsAccess to required business services, no blanket access to technical networks
Servers and servicesServers, NAS, directory and backup servicesPermit only required ports from defined source networks
GuestsPrivate devices and visitorsInternet access, client isolation and no internal destinations
IoT and building systemsDisplays, printers, sensors, control equipmentIsolated by default, with specific exceptions for management and required cloud targets
Protect and physical securityCameras, recorders, door accessSeparate from the normal client network, with administration and data flows explicitly allowed
This is a starting point, not a rigid template. Form zones around protection needs, operational ownership and required communication paths.

Segmentation without rules is only tidiness

Every connection between two zones needs a purpose, an owner and the narrowest practical permission. Temporary exceptions need an expiry date. Otherwise the firewall becomes an untestable patchwork over time.

If cameras are part of the project, recording, permissions and privacy deserve a separate workstream. The guide to UniFi Protect and GDPR-compliant workplace video covers those decisions.

6. Plan Wi-Fi as a radio network, not an accessory

Do not derive access point count from a generic square-metre figure. Walls, ceilings, shelving, machinery, neighbouring networks, client types and concurrent activity all change the outcome. Each radio cell must also fit the cabling and PoE plan. Vendor antenna patterns support predictive work, but they cannot replace measurements in the real building.

  • Mark capacity zones: meeting rooms, training areas, waiting rooms and production may require more AP capacity than corridors and storage.
  • Choose mounting positions from antenna behaviour and usage, not the most convenient empty wall or power outlet.
  • Keep the SSID count small, and assign every SSID a purpose, VLAN and security requirement.
  • Assess 2.4, 5 and 6 GHz separately because coverage, interference, channel supply and client support differ.
  • After installation, validate coverage, interference, utilisation, throughput, latency and roaming with representative endpoints.

The full radio workflow, including material assessment, channel design, site survey and acceptance testing, is covered in Planning UniFi Wi-Fi properly: coverage, channels and roaming.

7. Add headroom and resilience deliberately

Headroom is capacity for expected change. Resilience is an alternative operating path when something fails. Both cost money and should follow the business impact of an outage. A second gateway achieves little if both internet circuits share the same building entry point, or if the only switch and UPS remain common points of failure.

  • Allow free ports, PoE power, rack space, electrical capacity and uplink capacity for realistic expansion.
  • For critical sites, assess two independent WAN paths, including route diversity, provider equipment and a tested automatic failover process.
  • Configuration backups, documented recovery procedures and available spare units are often more economical than full duplication.
  • Calculate UPS runtime for the whole system: gateway, switches, controller, modem and critical PoE consumers.
  • Plan high-availability features such as Shadow Mode only after model support, cabling, test procedures and operational ownership are clear.

8. Documentation and rollout are part of the architecture

Document the target state, dependencies and rollback path before cutover. A small network does not need a hundred-page operations manual, but without a port map, IP plan and access model, even the first device replacement becomes unnecessarily risky.

  • Network diagram with devices, uplinks, cable identifiers, WAN handoffs and power supplies.
  • VLAN, subnet, DHCP, DNS and SSID plan, including the firewall rule matrix.
  • Switch port list with profile, speed, PoE mode and attached device.
  • Administration model with personal accounts, roles, multi-factor authentication and securely retained recovery information.
  • Acceptance record for internet, internal services, VPN, Wi-Fi, guest access, telephony and agreed failure scenarios.
  • Change and rollback plan for migration, ideally in verifiable stages rather than one undivided big bang.

9. Operations: the network remains a living system

New endpoints, neighbouring networks, firmware and applications change the starting conditions after go-live. Configuration backups, staged updates, alerting, capacity monitoring and regular recovery tests therefore belong to operations. Treat VLAN and firewall changes as small projects: record the purpose, test, document and roll back if necessary.

For a broader view of the platform, read UniFi in business: strengths, limitations and cost model. If you want to compare its licensing and support model with an enterprise cloud platform, see the UniFi versus Cisco Meraki comparison. I combine design, implementation and ongoing operations in my UniFi networks for businesses service.

Sources

This article is carefully researched guidance, not legal or tax advice. For binding information, please consult your tax advisor or lawyer.

Frequently asked questions

Which UniFi components does an SME need at minimum?+

That depends on the architecture. A gateway or other firewall, managed switches, appropriately placed access points and a UniFi host for the Network application are common. Quantity and performance follow from WAN, ports, PoE, VLANs, radio capacity and outage requirements, not a generic employee count.

How much switch headroom should I allow?+

There is no useful universal percentage. Plan separate headroom for ports, total PoE availability, PoE class per port, uplinks and rack power. Base it on known changes and the expected service life, then check endpoint maximum draw against the exact switch data sheet.

Does every device need its own VLAN?+

No. Segment by protection need, function and required communication paths. Employees, guests, management, servers, IoT and physical security are often useful zones. Too many tiny VLANs increase operational effort without automatically improving security.

Are VLANs already a firewall?+

No. VLANs separate broadcast domains and assign devices to networks. Routing and firewall rules determine whether traffic between those networks is allowed. Every permission should be narrow, documented and testable.

Does UniFi require controller licenses?+

Core UniFi Network management has no mandatory controller license. Depending on the operating model, optional services such as vendor hosting, additional security offerings or support may be paid. Hardware, design, operations and service-provider work remain cost items, of course.

When is redundancy worth the cost?+

When the expected impact of an interruption justifies the additional capital and operating effort. Start with common failure points: power, WAN handoff, cabling, gateway, switching and configuration. Then decide whether spares, a second WAN, UPS capacity, redundant paths or true high availability are appropriate.

A UniFi network designed around your business

I assess your site, applications and risks, then design the gateway, switching, PoE, VLANs and Wi-Fi around them. You receive a traceable architecture instead of a shopping basket built on guesswork, including implementation and clear documentation.

Daniel Gläser

Daniel Gläser

Owner of Gläser IT-Solutions, Chemnitz

I build software and run IT infrastructure for small and medium businesses, from the first analysis to day-to-day operations. Everything here comes from real projects and is backed by sources.

More articles